Socket.IO Vulnerability in Open WebUI Affects Permission Checks
CVE-2026-44564
5.4MEDIUM
What is CVE-2026-44564?
Open WebUI, a self-hosted AI platform, has a flaw in its Socket.IO event handling. Prior to version 0.9.0, the system fails to properly verify write permissions when users with read-only access join document rooms. This oversight allows such users to emit update events that can alter the document's state, affecting all connected collaborators in real time. The issue is resolved in version 0.9.0.
Affected Version(s)
open-webui < 0.9.0
